What is a Security Data Lake?  Cyber Terms Explained

Featuring: Tal Mozes, CEO & Co-Founder, Mitiga 

When we talk about a Security Data Lake, Data Lake is not a very new concept. It's the concept of aggregating a lot of data from different resources into a centralized repository.

In the security world, before the Security Data Lake, is the logic that we add on top of the Security Data Lake in order to capture the right data for security reasons. Usually, people are referring to SIEMs as the place to aggregate security data. But we need to understand that the SIEM was not designed to aggregate all the data needed for security reasons, and to keep it for a long period of time.

It's optimized, mostly, to capture data, which is needed for monitoring and to keep it for a short period of time so you can investigate and triage alerts that you've found out through the SIEM. So, mostly, you will see data which is kept for either 90 days to 180 days max.

But when we're talking about nowadays, when the data size is huge and the SIEMs are not designed for that,  moving it into data lake will help you maintain the data for a longer time so you can always go back and search if you learn of a new type of incident or breach that could have happened on top of your data. It will also help you to look from a single pane of glass into multiple environments that you might have with different types of data, with a single query.

Learn about the benefits of Mitiga’s Cloud Security Data Lake, providing visibility into your complete cloud  ecosystem.

Video

What Is Cloud Investigation? Cyber Terms Explained

Maybe before we dive deep into cloud investigation, let's talk about what is the cloud that we're referring to in cybersecurity? Because the cloud has different parts in your organization.

Video

What is Cloud Incident Response? Cyber Terms Explained

Cloud incident response, process-wise, is not very different than a regular incident response—which is the process once we realize we have been breached. We need to start investigating what has happened, what is the impact, when did it happen, and what we need to return to business as usual as soon as possible.

Video

Mitiga — RSA Conference 2024 Innovation Sandbox

Each year, RSA Conference invites cybersecurity’s boldest new innovators to compete in RSAC Innovation Sandbox, a contest that puts the spotlight on startups with potentially game-changing ideas.